diff --git a/app/.snyk b/app/.snyk new file mode 100644 index 000000000000..902a0875c1ef --- /dev/null +++ b/app/.snyk @@ -0,0 +1,10 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - git-describe > lodash: + patched: '2020-05-01T05:54:51.440Z' + - lodash: + patched: '2020-05-01T05:54:51.440Z' diff --git a/app/package.json b/app/package.json index bd90baa772eb..2430fb3defcb 100644 --- a/app/package.json +++ b/app/package.json @@ -33,6 +33,12 @@ "semver": "5.5.0", "shell-env": "0.3.0", "uuid": "3.2.1", - "winreg": "1.2.4" - } + "winreg": "1.2.4", + "snyk": "^1.316.1" + }, + "scripts": { + "snyk-protect": "snyk protect", + "prepare": "yarn run snyk-protect" + }, + "snyk": true }